Modeling Information Leakage: A Probabilistic Strategy for Social Network Security

A probability-based approach to modeling the risk of unauthorized propagation of information in on-line social networks

2011-02-15
Barbara Carminati, Elena Ferrari, Sandro Morasca, Davide Taibi
Summary
Problem
Method
Results
Takeaways
Abstract

This paper proposes a probability-based framework to quantify the risk of unauthorized information leakage in On-line Social Networks (OSNs). The core method introduces the Unauthorized Access Risk (UAR) metric, which uses a recursive probabilistic model and a sharp upper-bound approximation to estimate the likelihood of resources reaching unauthorized users in topology-based access control systems.

TL;DR

As On-line Social Networks (OSNs) transition from simple communication tools to complex knowledge management systems, the risk of "unauthorized propagation"—where data leaks beyond the intended audience—has skyrocketed. This paper introduces a formal probabilistic framework to quantify this risk, moving beyond simple binary access controls to a nuanced Unauthorized Access Risk (UAR) metric.

The "Invisible" Threat in Topology-Based Access Control

The industry standard for OSN privacy is topology-based access control. You don't authorize "John Miller"; you authorize "Friends of Friends" or "Second-degree contacts."

While flexible, this creates an Intensional Uncertainty. In a network like Facebook or LinkedIn, an "n-th degree" rule might authorize thousands of strangers. Users have a physical intuition of their social circle but zero mathematical intuition of the information flow paths leading out of it. This paper addresses the fundamental "Why": Why do we lose control of our data? Because we cannot visualize the probability of a "well-meaning" friend passing a sensitive resource to a "malicious" unauthorized user.

Methodology: The Core Risk Engine

The researchers define the OSN as a tuple . The innovation lies in the labeling function lab, which assigns a propagation probability to every relationship.

1. Path-Based Propagation

The probability that a resource travels along a specific path is the product of the probabilities of each link:

2. The Border Problem

The most critical contribution is the definition of Border Unauthorized Nodes (BorderUnAuth). These are the "gateways" to leakage—users who are not authorized to see the data but are directly connected to someone who is.

Network Hierarchy and Border Nodes Figure: An example hierarchy showing how information flows from the owner through authorized nodes to the unauthorized border.

3. Solving Complexity with Upper Bounds

Calculating the exact probability across all possible paths is NP-hard (exponential growth). The authors propose a sharp Upper Bound () approximation that reduces complexity to , where is the number of arcs. This makes the risk calculation feasible for real-time systems.

Experimental Insights

The authors validated the model using two distinct scenarios:

  1. Low-Probability OSN: Simulating a "tight-lipped" community.
  2. High-Probability OSN: Introducing "super-spreaders" (10% of nodes with >0.9 propagation likelihood).

Experimental Results Figure: Comparison of UAR values. The "jump" in the trend line effectively detects the presence of high-risk propagation nodes.

The results show that the UAR metric is highly sensitive to the presence of high-risk actors. Even if your access policy remains the same, if your "friends" become more likely to share data, your UAR score will spike, providing a proactive warning.

Critical Analysis & Conclusion

This work shifts the focus of social network security from static permissions to dynamic flow risk.

Takeaways:

  • Proactive Privacy: Instead of just setting a "Private" flag, users could receive a "Risk Score" (0.0 to 1.0) before they hit post.
  • Enterprise 2.0 Application: In corporate environments, this helps compliance officers identify high-risk internal paths for sensitive intellectual property.

Limitations: The current model assumes propagation probability is independent of the resource type. In reality, a "funny meme" has a higher than a "quarterly financial report." Future work needs to integrate Content-Aware Propagation to refine these risk estimates.

Ultimately, this probability-based approach provides the mathematical rigor needed to reclaim control in an increasingly interconnected social world.

Find Similar Papers

Try Our Examples

  • Search for recent studies that extend this probability-based risk modeling to modern hyper-scale social networks using Graph Neural Networks or distributed computing.
  • Which papers first established the FOAF (Friend of a Friend) vocabulary standards mentioned here, and how have they evolved to include privacy metadata?
  • Examine how the Unauthorized Access Risk (UAR) metric can be adapted for data leakage prevention (DLP) in Enterprise 2.0 collaborative platforms like Slack or Microsoft Teams.
Contents
Modeling Information Leakage: A Probabilistic Strategy for Social Network Security
1. TL;DR
2. The "Invisible" Threat in Topology-Based Access Control
3. Methodology: The Core Risk Engine
3.1. 1. Path-Based Propagation
3.2. 2. The Border Problem
3.3. 3. Solving Complexity with Upper Bounds
4. Experimental Insights
5. Critical Analysis & Conclusion